Trojan.Agent/Gen-FakeAlert[Local] CAPABILITYTABLE.EXE

Discussion in 'Malware Help (A Specialist Will Reply)' started by CloseShave, Apr 8, 2010.

  1. CloseShave

    CloseShave Private E-2

    I am pissed Norton did not find this. I was always under the impression Norton was the best there is/was. I am shocked spybot and others did not find it as well.

    I do not know what I am infected with but, if I had a virus/trojan which desires to steal my CC info/PWs the errors make sense.

    3 weeks ago things started going 'odd'. The computer never seemed slow but issues in event viewer started popping up. Dcom, .Dll, Winlogin(I think it is called), DCHP, Winint(spelling). Iexplorer would randomly lockup or hang. When ran as admin the lockups/hangs were less frequent but still common. Firefox locks up/hangs as well. However, in comparison not as frequently. Over this three week period(or was it 2 weeks) I received 2 separate mem dumps(bsod). Tech support described them as bad hardware that I needed to send back. Or they were just strange. I scanned with Norton and others but found nothing. Many still insist it is hardware - I am not sure. It has signs of software issues not hardware, I have that feeling from what I have personally experienced. If it is determined here the viruses/malware could not have called the above issues I guess I drop $100 to a tech so they can swap components. The oddest thing which happened was I was unable to boot my computer from a warm boot. However, cold worked 99.9% of the time(BootStrap/MBR/Interrupt 19 - whatever). Everyone screams BAD RAM BAD RAM. I did the gold standard Mem86 for both sticks - issue free. I have had over 28 unique errors in my event viewer which were responsible for well over 3,000 errors for the week. I also noticed my computer was reporting 100 anonymous logon/logout in my security logs per hour - if not more. I was also receiving memory leak errors. According to task manager and other diag tools this was not the case. Another strange thing I was receiving many privileged issues, I could not save to my root dir and other things. Also the registry entries which related to user accounts reported errors on occasion. I have notes, error reports and screen shots. This could be a combination of hardware/software/virus.

    But, if a program was trying to send data from my cpu elsewhere possibly many of the event viewer errors make perfect sense now?

    I did not remove:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> No action taken.
    Per this thread and many others it is "ok":
    http://forums.malwarebytes.org/index.php?showtopic=7653&st=0

    Finally here is a more detailed report of my errors. I was reaching out for help on the free Microsoft forums:
    http://social.technet.microsoft.com...l/thread/51e8b31f-5a46-4804-ab99-09e34b4e14f4

    http://social.technet.microsoft.com...l/thread/f94009c8-5e56-4903-b503-223e9710936a

    **Main description:http://social.technet.microsoft.com...l/thread/51e8b31f-5a46-4804-ab99-09e34b4e14f4

    Thanks!

    Lastly I watch but not download porn - I guess that is still bad? :(
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to tell us exactly what is reported......the full path to the file.

    Also, you should not have BitTorrent running at start up.

    What is this> C:\Windows23?

    You should clean out this folder:
    C:\Users\Daddy\Local Settings\TEMP
     
  3. CloseShave

    CloseShave Private E-2

    Hi, Hi!

    Thank you! Darn good eye! Win23 was a folder I created. I forgot it was there. Unless I am told differently I am just going to delete it.
    :When someone else was going to use my computer I was going to use this to store personal files - hence hidden with possibly some strange privileges.

    You should clean out this folder:
    C:\Users\Daddy\Local Settings\TEMP
    This folder clean

    Also, you should not have BitTorrent running at start up.
    In the next 15 minutes BitTorrent will no longer run at start up, thank you

    You need to tell us exactly what is reported......the full path to the file.
    Huh? The virus I mentioned? Sorry, SaS found it. I have no clue what the log means. However, that is what I was talking about - the information referenced in that log.

    If anything additional is needed please let me know.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right, sorry, brain took a leave. Since SAS dealt with the files, I am not seeing anything else in your logs. What issues are you having now?
     
  5. CloseShave

    CloseShave Private E-2

    Oh . . . !@#$#@#$ Nothing huh? Well damn!
    C:\WINDOWS.OLD\USERS\DADDY\APPDATA\LOCAL\TEMP\{0DF01249-5A6A-450F-91DA-08AAC0EA2475}\{DE4DF4A7-8E12-41EE-B7DD-1A9E6E4117EB}\CAPABILITYTABLE.EXE

    Above was the issue found by SaS.

    As far as problems I am having now they are out of the scope of this section of the forum. Not sure if you do tech help here at geeks in other sections.... But, in brief out of the blue 2-3 weeks ago my 5 month old CPU started hanging. Sometimes the hangs would lead to freezes(lockups) other times it would 'adjust and fix itself' if I just stared and used my mind powers "Work! Work! Work!". Usually when it froze the screen would go 'whiteish'(I just made that word up). I was and am having privilege issues where I can not do "X" "Y" & "Z". One of them I remember not being able to save to my root(C:\) drive. I just ignored it and saved elsewhere. Other times I just shift clicked and ran as admin or sometimes it allowed me to take control. I know windows is like this(privledge issues somewhat normal) but recently it has been excessive. There have been 2 BSOD errors - still working to figure them out exactly. And many errors/warnings in my Event Viewer. They seem mostly to tie back to reporting hangs, .dll files, registry issues, winint, DNS and uhhh winlogon. For a day or two I was getting tons of reports that "An account was successfully logged on." in excess when compared to previous logs. Also a lot of Anonymous Logons which seemed excessive. I know sometimes both are the norm. Others of this nature which seem to begin in excess 3-4 weeks ago. I've not counted em, I know it is a norm, so I am told. So most likely it is my imagination.The biggest and oddest problem. Is I can cold boot but not warm. Warm locks up after the post test or there abouts. I know that shouts RAM. I pulled it, examined it... Memtested both sticks for hours. Doc Watson, SiSoftware Sandra, tested HD, temps are fine.

    I am doing my A+ classes now. Sometimes I think I know more than I do. I did something somewhere? My gut(a tech or man of science never trusts their gut - LOL?)... My gut says it is software. Rather than throw up my hands and do a system restore, my gut might be wrong and it might be hardware. So a sys restore would not help. I want to work to address each of these odd issues in event viewer. I have thrown myself to the wolves. Microsoft seems to call it their free customer service. 80% of the time I do not understand the cause or the solution is when mods help me on MS forums - it is PHD geek greek.. However, I can read, follow and implement what they tell me to do. So, in a few weeks if I do not drown in the Microsoft tsunami of loving customer service and all the errors are clean I am still in the same boat I will drop $100-200 on a tech to tell me what part I need to replace. Then buy me a new 1.

    That is my story. I am sticking with it! I mention it again. Possibly this will jog a malware/virus thingy in your mind. If not cool - thanks for taking a look!!!!!!!!!! For a moment if a program was trying to log in and export information from my computer possibly it went into my MBR(or something) and created an account(changed privileges) and used my network to get out. I thought that might explain alot of these errors. I guess it was my imagination.

    Thanks man thanks!
     
  6. CloseShave

    CloseShave Private E-2

    Hey? Hey? One final creepy thing? My .dmp file. Well, they are stored in my c:\win\minidump dir(or whatever it is exactly called). Well, it is gone! Poof - vanished. Possibly I accidentally deleted it? Possibly my system is just corrupt as heck heading down hill to its death. Do not think it is relevant. But, worth a mention.

    Again!!!!! THANKS for taking a look!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I would suggest that you start a thead in the software forum. Although this could be a heat issue, it could also just be a software one. ;)
     
  8. CloseShave

    CloseShave Private E-2

    Understand 100% thanks
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. And good luck. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds